CVE-2014-9971Improper Input Validation in INC Snapdragon Mobile

Severity
9.8CRITICALNVD
EPSS
0.3%
top 47.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 18
Latest updateMay 14

Description

In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon_mobileMDM9635M, SD 835

🔴Vulnerability Details

1
GHSA
GHSA-gf7m-q852-q3hm: In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be2022-05-14

📋Vendor Advisories

1
Android
CVE-2014-9971: Closed-source component2018-04-01